Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Hunting Windows Desktop Window Manager Bugs

Hack In The Box Security Conference via YouTube

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the intricacies of Windows Desktop Window Manager (DWM) vulnerabilities in this 46-minute conference talk from Hack In The Box Security Conference. Delve into the architecture of DWM and its interaction with low-privileged users, uncovering a significant attack surface within the Windows graphics component. Examine 10 discovered bugs in the DWM process, all acknowledged by Microsoft, and gain insights into the reverse engineering process that revealed special features like restart recovery and exception handling. Learn about six specific vulnerability cases, including out-of-bound access, untrusted pointer reference, type confusion, and use-after-free issues. Understand the implementation details of DirectComposition in user and kernel modes, and discover the security challenges in shared memory communication. Compare manual code auditing and fuzzing techniques for vulnerability detection, and grasp the importance of auditing user-mode code in addition to kernel-side vulnerabilities.

Syllabus

#HITB2023AMS D1T1 - Hunting Windows Desktop Window Manager Bugs - Z. WangJunjie, Y. He & W. Li

Taught by

Hack In The Box Security Conference

Reviews

Start your review of Hunting Windows Desktop Window Manager Bugs

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.